TC Tools

OASIS provides a variety of optional-use tools to its members so they can more effectively perform their collaborative work. Any Technical Committee may request activation of these tools by submitting a request form: JIRA, SVN, Wiki or GitHub. Optional tools include, for example:

Many OASIS TCs also make use of the SOAPHUB WebConf meeting management tool, although it is unofficial (maintained by Doug Davis rather than by OASIS).

In an effort to accommodate TCs with multiple editors and support the use collaborative authoring/editing tools that are not not inherently part of the Kavi (TC Document Repository) application, the following policy is set forth to provide a set of guidelines related to the use of collaborative authoring/editing/versioning system.

The site and all of its contents must be publicly viewable/readable by the general public.

The site and access to all of its contents must not require a login for read-only access.

The TC home page:

The location (URI) and a brief description of each site (Wiki, Issues, Version Control Repository) must be posted on TC public home page and maintained by the TC Chair and/or Secretary.

Access Permissions:

Write access must be provided to all TC Members (Members, Voting Members, Persistent Non-Voting Members, Chairs, and Secretaries).

TC Observers and the general public must not be allowed write access.

TC Document Repository (wiki and version control only at this time)

At least once a month (unless no work has been done), and prior to each TC meeting at which one or more draft documents will be discussed, Working Draft level material for any/all such documents must be uploaded to the TC document repository, properly identified according to the OASIS Naming Directives; links to the non-Kavi publication venues are insufficient

All TC member reviews and ballots must be based on Working Draft level content as posted to the TC document repository (links to the non-Kavi system are insufficient)

Connect with OASIS

Testimonials

Cybersecurity is one of the greatest challenges our modern society faces and requires a coordinated approach to succeed. Under OASIS leadership, we see an opportunity to better organize the good guys to fight cybercriminals by sharing cyber threat intelligence data in an automated and efficient data standard.

As a Sponsor of the OASIS CTI Technical Committee, we are delighted to be at the forefront of advancing critically important standards like STIX, TAXII and CybOX. By creating protocols that address how to best model, analyze, and share cyber threat intelligence, we can provide greater support to overwhelmed security professionals.

Soltra is proud to be a member of the OASIS CTI Technical Committee. Our threat information sharing solution, Soltra Edge, was built leveraging STIX, TAXII, and Cybox – key standards within the industry. We look forward to contributing to CTI as we continue to establish and maintain open standards, while improving cyber security capabilities and reducing workload.

Open standards and community sharing are vital components of a successful and effective fight against cybercrime. Our goal is to make Threat Intelligence, from a variety of sources, timely and actionable.

Focusing on standardizing threat intelligence technologies to keep sensitive government and corporate information secure is paramount to the mission of OASIS and its members. At ViaSat, we take a comprehensive approach to cybersecurity, from identifying potential cyber and physical security vulnerabilities to designing and implementing a plan that leverages big data analytics, intuitive visualization and intelligent automation to keep pace with evolving threats no matter where data resides on the network or how it is accessed.

iSIGHT Partners, creator of the commercial cyber threat intelligence category, understands how security organizations can gain the advantage over adversaries by using threat intelligence across their security and risk management program. As an early contributor and enabler of STIX, we welcome the opportunity to join with OASIS to further develop CTI standards and accelerate the adoption of context rich threat intelligence.

At OASIS, you don't have to be a large vendor to influence work. Of all the standards bodies we’ve participated in, OASIS is the only one we recommend with no hesitation. It is a group that simply works.

We are proud to support the work OASIS is doing to advance their cybersecurity specifications and promote information sharing, a critical factor in today's security posture. By sharing details about malicious incidents quickly, not only between the public and private sectors, but across industry lines within the private sector as well, we can work together to better defend ourselves and stay ahead of the hackers.

STIX and TAXII in particular are important initiatives towards next generation threat intelligence. Using the same terms, data streams, and threat modeling methods will help researchers, vendors, and law enforcement alike share information back and forth to stay abreast or even ahead of threat actor groups. We are pleased to contribute to this and more through OASIS.

We have long been committed to any advances that can better enable the sharing of threat intelligence among security professionals. Until now, organizations have been hampered by a lack of common standards and the tendency for security information to be siloed. We strongly support this important endeavor and look forward to contributing to the standardization being led by OASIS.

NEC is very pleased to be part of the CTI Technical Committee and continues to drive CTI adoption with industry partnerships to benefit customers. NEC believes that threat intelligence standards are crucial for proactively countering the cyber threat. We are excited about the formation of CTI TC and support its efforts through its contributing to and promotion of this global standard.

We have been advocates of STIX, TAXII and CybOx for some time. OASIS as an international standards checkpoint will undoubtedly improve threat intelligence sharing amongst partners by facilitating the exchange of computer-readable threat information.

Development of an industry-wide standards framework for cyber threat intelligence is crucial for the information security industry to be able to define and share threats. New Context is a proud sponsor of OASIS and believes strongly in open and transparent standards frameworks development. We look forward to collaborating on the next standards for STIX, CybOX and TAXII.

I always encourage vendors with products related to access control, security, or cloud computing to join the appropriate OASIS Technical Committees and contribute to the standards work. We all benefit that way.